Spyware disguised as emergency-alert app sent to Israeli smartphones

2026-03-06T19:24:01Z8720579e431325735efa4af3725e5156db9a339f02dbd1e5e2f7500f32256962
Bing AI search abuse','GitHub malware','Perplexity Comet','localChrome GeminiCisco SD‑WANClickFixGoogle zero-dayHamasIranLexisNexisLummaMuddyWaterOpenClawReact2Shell (exploit claimed)TfLTransport for LondonWindows Terminalactive exploitationbrowser securitydata breachinfostealermalicious installersnation-stateprivilege escalationsocial engineeringspywarevulnerability

What happened

A large set of security incidents and trends: Hamas-linked actors are distributing spyware disguised as an emergency-alert app to Israeli users via SMS (stealing SMS, location, contacts). Multiple Cisco SD‑WAN vulnerabilities are under active exploitation (file overwrite/privilege escalation). A ClickFix copy‑paste social‑engineering campaign lures users to run commands in Windows Terminal, delivering the Lumma infostealer. Google reports a record number of zero‑days in 2025, with China‑linked groups and spyware authors prominent. Iranian‑linked operators (MuddyWater and others) have backdoord

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
8720579e431325735efa4af3725e5156db9a339f02dbd1e5e2f7500f32256962
Enrichment time
2026-03-06T19:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.